Security Leftovers
-
Ransomware gang releases new data stolen from the City of Oakland [iophk: Windows TCO]
The Play ransomware group shared 600 gigabytes of data on its leaks site in its second release, including Oakland Police Department files, council members’ communications and city staff’s medical records. By contrast, the first release of stolen data in March was a more modest 10 gigabytes.
The ransomware attack took place on Feb. 8, knocking some of the city’s information technology systems offline. The city declared a state of emergency on Feb. 16 because of ongoing network outages caused by the attack. The attack did not affect 911 services, but certain nonemergency systems were forced offline.
-
Cisco Patches Code and Command Execution Vulnerabilities in Several Products
Cisco has released patches for high-severity vulnerabilities impacting Secure Network Analytics and Identity Services Engine (ISE) products.
-
Microsoft leads effort to disrupt illicit use of Cobalt Strike, a dangerous [cracking] tool in the wrong hands [Ed: Gross and negligent inversion of narratives; the culprit here is Microsoft, Microsoft isn't the solution]
The action against illicit versions of legitimate Cobalt Strike applications represents the culmination of a year-long investigation.
[...]
Cobalt Strike, an adversary emulation tool that information security professionals use to evaluate network and system defenses to enable better security, like other legitimate hacking tools, is regularly abused by cybercriminals as part of attacks ranging from financially motived cybercrime to high-end state-aligned attacks.
-
Thieves Use CAN Injection Hack to Steal Cars
An innocent-looking portable speaker can hide a hacking device that launches CAN injection attacks, which have been used to steal cars.
[...]
Specifically, the thieves pulled off the bumper and unplugged the headlight cables in an attempt to reach wires connected to an electronic control unit (ECU) responsible for the vehicle’s smart key.
-
Success of Genesis Market Takedown Attempt Called Into Question
Law enforcement announced the takedown of Genesis Market, but the impact on the cybercrime marketplace’s infrastructure may be limited.
-
Several Distros Release Important Advisories for Actively Exploited Linux Kernel Use After Free Vuln
Several high-impact security vulnerabilities were recently discovered and fixed in the Linux kernel. These flaws could result in memory exhaustion, system crashes, denial of service (DoS), the exposure of sensitive information, cross-site scripting (XSS) attacks, privilege escalation attacks, or the execution of arbitrary code.